CISM Information Security Risk Management Practice Question
A retail company has a documented risk appetite stating that it will accept no more than a moderate level of risk to customer payment data. A recent assessment shows the payment environment carries a high residual risk after existing controls. What should the information security manager do FIRST?
⚠ Common exam trap
The trap here is choosing immediate remediation or quietly adjusting the appetite statement, when the governance-correct first step is escalating the appetite breach to the accountable executives.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Escalate the residual risk to senior management as a risk above the approved appetite.
Risk appetite defines the amount of risk leadership is willing to accept in pursuit of objectives. When residual risk exceeds that boundary, the information security manager's first obligation is to escalate the exception to senior management, who own the decision to remediate, accept, or adjust strategy. Acting unilaterally or rewriting the appetite statement would bypass proper governance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Document the residual risk in the risk register and continue monitoring it on the normal reporting cycle.
Why it's wrong here
Routine documentation and monitoring are appropriate for risks within appetite, not for a high residual risk that breaches a stated tolerance for payment data. Treating an appetite violation as business as usual delays necessary executive action. The manager must escalate the exception promptly so leadership can decide on treatment before the exposure results in a payment data incident.
- ✓
Escalate the residual risk to senior management as a risk above the approved appetite.
Why this is correct
When residual risk exceeds the documented risk appetite, the gap is a governance issue that must be escalated to the risk owners and senior management who set the appetite. They are accountable for deciding whether to fund additional controls, accept the deviation, or change business plans. Informing them first ensures the decision is made at the appropriate authority level.
- ✗
Revise the risk appetite statement so the current residual risk falls within acceptable limits.
Why it's wrong here
Adjusting the appetite statement to legitimize an existing exposure is reverse-engineering governance to avoid a difficult conversation. Risk appetite is set by senior leadership based on business strategy, not by the security manager to match current conditions. Doing this would conceal a genuine gap in payment data protection and undermine the credibility of the entire risk management program.
- ✗
Immediately implement additional controls and then report the change in risk level.
Why it's wrong here
Implementing controls without approval may exceed budget, disrupt payment operations, and preempt the risk owner's authority to choose among treatment options. While remediation may ultimately be the answer, the manager's first duty is to surface the appetite breach so the accountable executives can direct the response and authorize any spending on payment environment safeguards.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.